2
I have exported the SAM and SYSTEM as Registry Hive Files and I was wondering if it is possible to look inside those files to see what they contain? I opened them with Notepad but I didn't see anything meaningful (to my eyes at least). So I used ophcrack to load the local SAM with samdump2 and I was able to get the NT Hash. I want to know if the SAM file can be read in any other way especially with text editors. Or maybe I should be asking how does samdump2 work?
Does Microsoft provide any information related to the issue at hand? – Django – 2016-01-13T19:52:05.263
About which isse exactly? – davidb – 2016-01-13T19:54:05.457
Accessing the source of the file? – Django – 2016-01-13T19:54:42.713
I have not read such but you can find some in the developer notes of pwdump7 – davidb – 2016-01-13T19:58:51.307
Will look at it. – Django – 2016-01-13T20:05:56.773